Skip to content

fix: Harden PayGate v4 authority and relay flows - #83

Merged
Phloraxx merged 32 commits into
mainfrom
fix/v4-focused-integration-20260906
Sep 10, 2026
Merged

Phloraxx merged 32 commits into
mainfrom
fix/v4-focused-integration-20260906

Conversation

@Phloraxx

@Phloraxx Phloraxx commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

Scope

Focused PayGate v4 hardening, exact-amount payment matching, and final parser/code-quality cleanup.

Payment matching

  • exact randomized payable amount + valid reservation window is the payment identity
  • payer name / payer UPI are metadata only and never block a unique exact-amount match
  • live payable amounts are globally collision-blocked across collection profiles
  • existing pre-upgrade cross-profile overlaps are grandfathered fail-safe until release
  • Paytm Business evidence stays profile-bound; trusted generic payment-app evidence is amount-matched globally
  • no tr dependency; PayGate does not rely on merchant transaction-reference support

Notification trust / parsing

  • server accepts payment evidence only from the trusted payment-app package set
  • Google Messages / Kotak SMS and Gmail / Slice email are rejected and do not become payment evidence
  • arbitrary app packages cannot enter generic payment matching
  • 1-decimal and 2-decimal INR amounts are parsed consistently (₹12.3 -> 1230 paise, ₹12.30 -> 1230 paise)
  • whole-rupee / .00 amounts remain excluded from PayGate randomized-amount matching
  • over-precision or malformed numeric tokens such as ₹12.345, ₹12.34.56, and ₹12.34foo are rejected without prefix truncation
  • sentence-ending punctuation and multi-amount ambiguity detection remain intact

Relay security

  • relay devices remain additive and independently revocable
  • new/re-paired devices use server enrollment epochs in request signatures
  • same-key re-pair invalidates captured prior-epoch requests, including same-millisecond re-pair cases
  • pre-rollout devices retain legacy-signature compatibility until re-paired
  • device authority remains evidence-only except the explicitly permitted active destination change

Storage / rollback

  • logical schema_migrations remains at v4 so the previous v4 binary can reopen the database during rollback
  • newer global-amount and enrollment-epoch safeguards are installed idempotently as compatibility schema
  • historical/transitional v5-v7 database shapes are recognized and normalized safely back to logical v4
  • the previous v4 storage.Open() was exercised directly against an upgraded database and succeeded
  • restore validation covers current, legacy-v5, and historical marker-aware transitional backups

Verification

Exact head: 28d44c331a887c083ffb54af92c55ba65eea949f

  • exact-head GitHub CI: PASS (34392894869)
  • frontend dependency scan, typecheck and production build: PASS
  • full uncached server tests: PASS
  • Go race tests: PASS
  • Go formatting + whitespace checks: PASS
  • go vet, static analysis and Go vulnerability scan: PASS
  • PayGate v4 container build: PASS
  • actual old-v4 storage.Open() rollback probe: PASS, schema remains 4
  • final cleanup Luna wave: amount grammar PASS 0.98, source policy PASS 0.99, security regression PASS 0.96
  • disputed whole-rupee / .00 reviewer finding independently adjudicated PASS 1.00
  • no surviving release blocker

No merge or production deployment is included in this PR verification.

@Phloraxx Phloraxx changed the title PayGate v4 authority, evidence, restore, and webhook hardening fix: Harden PayGate v4 authority and relay flows Sep 6, 2026
@Phloraxx
Phloraxx force-pushed the fix/v4-focused-integration-20260906 branch from 83b455b to b8aaf5b Compare September 7, 2026 20:24
@Phloraxx
Phloraxx merged commit e14f105 into main Sep 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant